Seeds for Thought9 min read

Preventing Payment Scams: A Guide for Philippine Businesses

Preventing Payment Scams: A Guide for Philippine Businesses

72% of surveyed Filipino consumers were targeted by a digital fraud attempt between August and December 2025. The global figure was 53%. That gap is not just a consumer problem. Every one of those attempts can have a business on the other side of it: a seller shipping goods against a fake receipt, a merchant dealing with a chargeback, or a finance team sending funds to a spoofed bank account.

If you accept online payments in the Philippines, you are already in scope. This guide covers the payment scams that actually hit Philippine businesses, the controls that stop each one, and what to do if money has already gone out the door.

Why Philippine businesses are a bigger target than most

The Philippines has recorded a suspected digital fraud rate above the global average for six consecutive years. In 2025, the local rate sat at 4.1% against a 3.8% global level, according to TransUnion's 2026 State of Omnichannel Fraud Report.

The more useful detail is what kind of fraud is costing businesses. In BSP's 2025 cyberthreat surveillance, social engineering, account takeover, and identity theft together accounted for 76% of reported financial fraud losses. Hacking accounted for 13%, while card-not-present fraud accounted for 8%.

That changes what you should be spending on. The threat is not only someone breaking into your systems. It is also someone convincing a person on your team, taking over an account, or exploiting a payment process you never tightened up. Anti-virus software alone does not fix that. Better payment operations matter too.

The 6 payment scams hitting Philippine businesses right now

1. Fake payment screenshots and edited e-wallet receipts

One of the simplest scams targeting Philippine sellers is a fake payment receipt. A "buyer" sends a screenshot of a GCash, Maya, or bank transfer confirmation. The seller ships. The money never arrives.

Fake receipts can be made to look convincing, which is why visual inspection alone is not a reliable control.

How it gets you: manual verification. Any process where a human looks at an image and decides whether money moved can fail.

There is no fake screenshot if you never ask for one

A screenshot is a picture of a payment. A payment link is the payment itself.

When you send a PayMongo Payment Link or Page, your customer pays through it and your dashboard marks the order paid the moment the funds clear. Nobody sends you an image. Nobody inspects one. The entire scam depends on a judgment call that no longer exists in your process.

It takes about two minutes to set up, works over Messenger, Instagram, Viber, or SMS, and costs nothing until you get paid.

Create your free PayMongo account

2. Chargeback abuse (friendly fraud)

The customer pays with a card, receives the goods, then disputes the transaction with their issuing bank, claiming the payment was unauthorized or that the purchase was not received. If the dispute is upheld, the transaction amount may be reversed and the merchant may also face a dispute fee, depending on the payment arrangement.

Some disputes are genuine confusion. For example, a customer may not recognise the billing descriptor on their statement. Others may be deliberate. If you are new to how disputes work, start with our explainer on what a chargeback is before you build your defense.

3. Card testing

Scammers take a list of stolen card numbers and run small transactions through your checkout to find which ones still work. You may see a burst of low-value attempts, mostly declined, often within minutes or at unusual hours.

Even when the attempts fail, a card-testing attack can create operational problems: more declined transactions, lower payment approval rates, and additional fraud-monitoring work.

4. Phishing and payment detail redirection

Someone impersonates a supplier, a landlord, or your own executive and emails a request to update bank details before the next payment. The invoice looks right. The email address is one character off. Finance pays the new account.

This is one example of the broader social-engineering problem reflected in BSP's fraud data. It targets your people and your processes, not just your infrastructure.

Scammers can impersonate a business or send customers payment instructions that appear to come from a legitimate seller. In physical stores, a QR code can also be replaced or covered with another code that directs the customer elsewhere.

The damage can be doubled: the business loses the sale, while the customer loses money believing they paid the business.

6. Overpayment and refund scams

A "customer" pays more than the invoice, then asks for the difference back to a different account. Or they claim a duplicate charge and request a refund to a new destination. If the original payment is later reversed as fraudulent, the business may be left without both the original funds and the refund.

A key warning sign is pressure to send money back quickly, particularly when the requested refund destination does not match the account or payment method used for the original transaction.

How to prevent payment scams: 8 controls that actually work

You do not need every control on day one. Start with the processes that remove the most obvious opportunities for fraud, then build from there.

Step 1: Stop accepting screenshots as proof of payment

This is one of the simplest changes you can make, and it costs nothing.

Make it policy: a screenshot is never proof. Payment is confirmed when the funds appear in your account or your payment dashboard. Write it down, tell every staff member who releases goods, and put it in your order confirmation message so buyers know before they ask.

Step 2: Use a payment channel that confirms for you

The reason screenshot fraud works is that person-to-person transfers can leave verification to the seller. A payment channel with a merchant dashboard gives you a transaction record you can check instead.

With PayMongo Payment Links, you send a link, the customer pays, and the payment is recorded in your PayMongo dashboard. There is no need to rely on a screenshot as proof of payment.

The same principle applies to QR Ph: use a business payment channel rather than asking customers to send money to a personal account.

If most of your sales come through e-wallets today, our guide on how to accept GCash payments walks through moving from a personal number to a business payment setup.

Step 3: Turn on 3D Secure for card payments

3D Secure adds an authentication step that can help verify that the person making a card payment is the legitimate cardholder. It can be an important layer of protection against certain types of card fraud and card testing.

It can also provide liability protection in qualifying circumstances, but it is not blanket chargeback protection. Liability depends on the authentication result, transaction type, card-network rules, and the reason for the dispute. Disputes involving issues such as goods not received, goods not as described, or duplicate billing are not automatically covered simply because 3DS was used.

Step 4: Set velocity limits and basic fraud rules

Card testing often produces a recognizable pattern: multiple payment attempts within a short period, particularly when several transactions come from the same customer, device, IP address, or card.

If your payment or e-commerce platform supports it, set reasonable limits on repeated attempts and flag transactions that differ significantly from your normal pattern. You can also review orders that are unusually large relative to your typical basket size.

The exact controls available will depend on your payment setup and fraud tooling, so configure the rules your system actually supports rather than relying on a generic checklist.

Step 5: Lock down your own accounts

Turn on two-factor authentication for every account that touches money: your payment dashboard, business email, bank portals, and e-commerce admin.

Give each staff member their own login instead of sharing one. Remove access when someone leaves the business.

Account takeover is one of the fraud categories included in the 76% of reported losses attributed collectively to social engineering, account takeover, and identity theft in BSP's 2025 cyberthreat surveillance.

Step 6: Verify every change to payment details out of band

Make it a rule that no change to a supplier's bank account, e-wallet, or payout destination takes effect based solely on an email.

Call the contact using a phone number you already have on file, not the number included in the message requesting the change.

A separate verification step can catch payment-detail fraud before the money is sent.

Step 7: Keep evidence that wins disputes

When a chargeback lands, you have a limited period to respond, and your evidence can be critical to the outcome. Keep, for every order: proof of delivery with a signature or timestamp where applicable, the customer's order confirmation, relevant communication history, and transaction information available through your payment system.

Also fix the boring things. Use a clear billing descriptor so customers recognise your business on their statement, publish your refund policy where buyers see it before checkout, and respond to complaints promptly. Making it easy for customers to understand and resolve legitimate issues can help reduce avoidable disputes.

Step 8: Train the team and write it down

Every control above fails if only one person knows about it. Put your rules in a one-page document: what counts as proof of payment, who can approve a refund, what to do when a supplier changes bank details, who to escalate to. Walk new hires through it. Review it every quarter.

What to do if you have already been scammed

Move quickly. The sooner your bank, e-wallet, or payment provider knows about a suspected fraudulent transaction, the sooner it can assess what recovery or holding mechanisms may be available.

  1. Report to your bank, e-wallet, or payment provider first. Under the Anti-Financial Account Scamming Act (Republic Act No. 12010), financial institutions have mechanisms for temporarily holding disputed funds in qualifying cases. BSP's implementing rules provide for an initial hold of up to five calendar days, with an additional holding period of up to 25 calendar days in qualifying circumstances.
  2. Then file with law enforcement. The PNP Anti-Cybercrime Group and the NBI Cybercrime Division handle cybercrime complaints. The DICT's Cybercrime Investigation and Coordinating Center also operates the 1326 anti-scam hotline. Bring transaction records, screenshots of communications, and the recipient's account details.
  3. Preserve everything. Do not delete the chat thread, the email, or the order. Export or save relevant records while they are still available.
  4. Tell your customers if they were targeted. If someone impersonated your business or cloned your payment instructions, communicate quickly with affected customers so they know what happened and what legitimate payment channels to use.

AFASA also establishes criminal penalties for certain forms of financial account scamming, including money mauling and social-engineering schemes. Reporting suspected fraud promptly can help authorities and financial institutions investigate the transaction.

Build your payment process so scams have fewer places to land

Many payment scams succeed because a business process leaves room for someone to make a judgment call, whether that means accepting a screenshot as proof of payment, changing a supplier's bank details based on an email, or issuing a refund without verifying the original transaction.

Remove those unnecessary judgment calls wherever you can.

That is what a proper payment setup can help with. PayMongo gives you a way to accept payments through cards, GCash, Maya, QR Ph, and online banking, with payment records available through your dashboard.

Create your free PayMongo account and stop verifying by eye.

Sign Up

Frequently asked questions

How can I tell if a GCash or bank transfer receipt is fake?

You often cannot tell reliably from the image alone. Fake receipts can look convincing, so the safer approach is to ignore the screenshot and verify the payment through your own GCash app, bank app, or payment dashboard. If the funds have not reached your account, do not treat the screenshot as proof of payment.

What should a small business do first to prevent payment scams?

Start by stopping the use of screenshots as proof of payment and use a payment channel that gives you a transaction record you can verify. Then add stronger controls such as two-factor authentication, staff access controls, fraud rules, and documented procedures for refunds and changes to payment details.

Can I get my money back if my business was scammed?

Sometimes, but recovery is not guaranteed. Report the incident to your bank, e-wallet, or payment provider as quickly as possible. Under AFASA and its implementing rules, financial institutions may temporarily hold disputed funds in qualifying cases, including an initial five-day period and a possible additional period of up to 25 calendar days.

You should also preserve the evidence and report the incident to the appropriate law-enforcement agency. The faster the incident is reported, the more information institutions have to investigate while the transaction can still be traced.

What is friendly fraud and how do I prevent it?

Friendly fraud generally refers to a cardholder disputing a legitimate transaction, whether because they genuinely do not recognise it or because they deliberately claim the transaction was unauthorized or that the purchase was not received.

You can reduce avoidable disputes by using a recognisable billing descriptor, publishing a clear refund policy, responding promptly to customer complaints, and keeping documentation such as order confirmations and delivery records.

Is it safe to accept online payments in the Philippines?

Online payments can be safe when businesses use established payment providers and follow basic security practices. Payment providers may offer security measures such as encryption, authentication, fraud monitoring, and transaction records, depending on the payment method and provider.

The important distinction is between using a proper business payment setup and relying on informal processes such as personal-account transfers or screenshots as proof of payment.

PayMongo is regulated by the Bangko Sentral ng Pilipinas and is PCI-DSS 4.0 and SOC 2 Type 2 Certified.